Getting Data In

Why is splunkd log not pulling the Windows event logs for application and security?

heats
Explorer

I pulled this from the splunkd log. I finally have my Windows 2016 box checking into Splunk. I can see it in Forwarder Management however it is not pulling the Windows Event logs for Application and Security.

Here's my inputs.conf:

[default]
host = ctw-ansible0101

[WinEventLog://Application]
disabled = 0
index = heats-test
[WinEventLog://Security]
disabled = 0
index = heats-test

[monitor://$SPLUNK_HOME\var\log\splunk\splunkd.log]
index = heats-test

04-25-2017 11:26:49.240 -0400 WARN IndexerService - Received event for unconfigured/disabled/deleted index=heats-test with source="source::C:\Program Files\Splunk\var\log\splunk\splunkd.log" host="host::ctw-ansible0101" sourcetype="sourcetype::splunkd". So far received events from 1 missing index(es).

This index is in Splunk so I'm not sure why it says it's unconfigured/disabled/deleted. Any ideas?

Labels (2)
0 Karma

harsaheb123
Observer

Search for the event log you are looking for in the search text box.

For eg:- if you want to search an event log with the name "TEST" search for-

TEST source="WinEventLog:Application"

in the Splunk search text box

0 Karma

heats
Explorer

Still no joy or logs coming in. No longer seeing any errors about indexes just not receiving the logs. I put an event into the Application log - can't find it in Splunk still.

0 Karma

adonio
Ultra Champion

Hello heats,
looks like your index is not configured correctly,
will recommend to use underscore and not hyphen for indexes names (and in splunk in general)
also check out this document for troubleshooting:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Troubleshooting/Cantfinddata

0 Karma

heats
Explorer

Created new heats_test index and made the changes in inputs.conf. Made a new event in the application log and restarted the splunk service. Still no joy - no logs coming in to the heats_test index. The good news is I don't see that error anymore in the splunkd log.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have a distributed Splunk system, make sure the heats-test index is defined on all indexers, not just the search head.

---
If this reply helps you, Karma would be appreciated.
0 Karma

heats
Explorer

We only have one indexer.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...